Skip to content
Foxx Cyberfoxxcyber/docs

Bedrock as Your ESP

How to scope and document Bedrock in your own SSP and assessment.

Under 32 CFR 170.4, an External Service Provider (ESP) is a provider whose assets process, store, or transmit your CUI or Security Protection Data (SPD). If you use the Bedrock CMMC platform, it stores SPD for your program — so document it. This page tells you exactly how, because a provider that makes you guess isn't doing its job.

What Bedrock is, per product

ProductRelationshipWhy
Bedrock CMMC (the SaaS platform)ESP — Cloud Service Provider for your assessment scopeIt stores your compliance working data (SPD): control statuses, POA&Ms, asset records, SSP content, and any files you upload
Bedrock C3PAO (the assessor app)Product, not an ESPIt runs air-gapped inside the operator's own boundary; no Foxx Cyber asset touches the data — see Where CUI Lives

Documenting Bedrock in your SSP

For the SaaS platform, we recommend:

  1. List Foxx Cyber LLC as an ESP in your SSP's external systems / service-provider inventory, described as a cloud-based compliance management service.
  2. State what it holds: Security Protection Data — compliance program metadata, control implementation records, POA&Ms, asset inventory, SSP content. Add "uploaded evidence files" only if your organization actually uploads evidence rather than using pointers.
  3. Reference the responsibility split: cite the Shared Responsibility Matrix (or the full CRM document, available on request) for which practices are provider-implemented, shared, or yours.
  4. Describe your own controls at the boundary: who in your organization gets accounts, role assignment, MFA policy, and offboarding — the customer-side responsibilities in the Customer Responsibility Matrix.

Assessors respond well to specificity. "We use Bedrock CMMC (Foxx Cyber LLC) as an ESP holding SPD; responsibilities are allocated per the vendor CRM dated X" is a complete, verifiable statement — and we'll supply the dated CRM to back it.

What you can get from us

As part of being a well-documented ESP, Foxx Cyber publishes the matrices as direct downloads — no request needed:

  • The full Customer Responsibility Matrix — all 110 CMMC Level 2 practices with the provider/customer/shared split and each side's portion spelled out (download CSV).
  • The domain-level Shared Responsibility Matrix (download CSV).
  • The Bedrock C3PAO deployment CRM for partners hosting the assessor app (download CSV).

Available on request, under agreement: the full System Security Plan and supporting documentation for assessor review, and partner-specific CRMs tailored to your deployment — through your Foxx Cyber point of contact or a support ticket.

Last updated July 29, 2026